Cross-Site Scripting Vulnerability in Sourcecodester FAQ Bot with AI Assistant
CVE-2025-63639
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 7 November 2025
What is CVE-2025-63639?
The chat functionality in the Sourcecodester FAQ Bot with AI Assistant v1.0 is susceptible to Cross-Site Scripting (XSS) vulnerabilities. This security flaw arises from inadequate sanitization of user-supplied input, allowing attackers to inject harmful HTML or JavaScript scripts into chat messages. Once injected, these scripts can execute in the browsers of other users participating in the conversation, potentially compromising sensitive information and leading to further exploitation. Proper validation and encoding of user inputs are essential to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
